Network Engineer interview questions

A network engineer interview is really a troubleshooting interview wearing a suit. They'll ask about routing protocols and subnetting, but what they're listening for is how you think when a link goes down and people are shouting in the chat. Here's what each round checks, the questions that come up most, and what separates a hire from a maybe.

The process

What happens in each round

  1. 1

    Recruiter screen

    What happens

    Whether your background matches the gear and scope in the posting. Expect questions about which vendors you've worked on (Cisco, Juniper, Arista, Palo Alto), whether you've run a campus network, a data center, or cloud networking, and whether you've been on an on-call rotation. Keep it short and name the platforms plainly.

  2. 2

    Technical phone screen

    What happens

    Fundamentals, fast. Subnetting in your head, the difference between OSPF and BGP, what happens when you type a URL into a browser, how spanning tree picks a root bridge. A senior engineer runs this and they're checking whether you actually know the packet path or just the certification vocabulary.

  3. 3

    Hiring manager

    What happens

    How you handle outages, change windows and other teams. The manager wants to know you won't push an untested change on a Friday afternoon, that you write things down, and that you can explain a problem to a server admin without sounding superior.

  4. 4

    Panel or lab

    What happens

    A whiteboard design or a broken lab. You might get a topology diagram with a routing loop, a packet capture to read in Wireshark, or a prompt like design a network for a new branch office. They care more about your questions and your order of checks than about the final answer.

Questions you're likely to get

1.Walk me through how you'd troubleshoot a user who says the internet is slow.

Why they ask

It's vague on purpose. They want to see whether you narrow the problem down in a sensible order or start rebooting things.

How to answer

  • Ask clarifying questions first: one user or many, one site or all, every app or one app, since when.
  • Work up the stack: link and interface errors, then IP and DNS, then the path with traceroute and latency checks.
  • Check interface counters for CRC errors, duplex mismatches and drops on the switch port.
  • Look at the WAN or firewall for saturation or a policy change, and check monitoring graphs for the time window.
2.Explain the difference between OSPF and BGP, and when you'd pick each.

Why they ask

It's the routing question that sorts people who've configured both from people who read about both.

How to answer

  • OSPF is a link-state interior protocol, fast to converge, good inside one organization.
  • BGP is a path-vector protocol built for policy between autonomous systems, and it's slow and deliberate by design.
  • Mention real uses: OSPF inside the campus or data center, BGP to ISPs, to cloud providers, or as the underlay in a leaf-spine fabric.
  • Name the knobs you've actually touched, like local preference, AS path prepending or OSPF area design.
3.A BGP session to one of our ISPs keeps flapping. What do you check?

Why they ask

Flapping sessions are a common real problem and they show whether you know BGP states and timers.

How to answer

  • Check the logs for the reason the session dropped, such as hold timer expired or a notification message.
  • Look at the physical link and interface errors, since a bad optic or cable causes a lot of flaps.
  • Verify timers, MTU and authentication match on both sides.
  • Check CPU on the router and whether a large route table is causing trouble, then open a ticket with the ISP with timestamps.
4.How does spanning tree work, and what's the worst spanning tree problem you've seen?

Why they ask

Layer two loops take down whole buildings. They want to know you respect them.

How to answer

  • Explain root bridge election, port roles and blocking in plain terms.
  • Mention rapid spanning tree and why you'd use it over the older version.
  • Talk about protections you'd turn on: BPDU guard, root guard, portfast on access ports.
  • Tell a real story, like someone plugging a cheap desk switch into two wall jacks, and how you found it.
5.Tell me about a change you made that caused an outage.

Why they ask

Everyone who's done this job has broken something. The interviewer wants honesty and what you changed afterward.

How to answer

  • Pick a real one and own it without blaming the change board or a vendor.
  • Explain how you noticed, how fast you rolled back, and who you told.
  • Describe the fix to your process: a pre-check script, a rollback plan, a peer review, a staged rollout.
  • Keep the story short and end on what you do differently now.
6.Design the network for a new branch office with a small staff, a printer, guest Wi-Fi and a phone system.

Why they ask

It's a quick design exercise that shows how you think about segmentation, security and cost at once.

How to answer

  • Ask about headcount, budget, what apps they run and whether there's a standard branch template already.
  • Separate traffic with VLANs: staff, voice, printers, guest, and management.
  • Put guest Wi-Fi on its own network with no route to internal systems, and apply QoS for voice.
  • Choose SD-WAN or a site-to-site VPN back to the data center, with a backup internet link if the budget allows.
7.What happens, step by step, when a laptop on the office network opens a website?

Why they ask

It tests whether you can follow a packet end to end, which is the whole job.

How to answer

  • DHCP has already handed out an address, gateway and DNS server.
  • The laptop resolves the name through DNS, then uses ARP to find the gateway's MAC address.
  • Traffic goes through the switch, the router, the firewall with NAT, and out to the internet.
  • The TCP handshake happens, then TLS, then the HTTP request, and the reply comes back through the NAT table.
8.How do you manage configuration across a lot of devices?

Why they ask

Teams are moving away from logging into boxes one at a time. They want to know if you've made that move.

How to answer

  • Talk about what you've actually used: Ansible, Python with Netmiko or NAPALM, or a vendor tool like Cisco DNA Center.
  • Mention keeping configs in Git and backing them up automatically.
  • Describe a real task you automated, like pushing an ACL change or auditing for a missing NTP setting.
  • Be honest about your level. Having written a few scripts is fine if you say so clearly.
9.How do you approach firewall rules when an app team asks you to open a port?

Why they ask

It's a daily request and it shows whether you balance security with getting people unblocked.

How to answer

  • Ask for source, destination, port and the business reason, not just open port so-and-so.
  • Keep the rule as narrow as possible and tie it to a ticket.
  • Check for existing rules that already cover it before adding another.
  • Mention periodic rule reviews to clean out stale entries.
10.Tell me about a time you had to explain a network problem to someone who wasn't technical.

Why they ask

You'll talk to managers, help desk staff and vendors. The network gets blamed for everything, so you need to explain calmly.

How to answer

  • Set up the situation briefly: who was affected and what they thought was wrong.
  • Explain how you put it in plain terms without talking down.
  • Show the result, like the manager approving a circuit upgrade or the app team fixing their own timeout.
  • Keep your tone generous toward the other person.
11.You're on call and get paged at night because a whole site is down. What do you do in the first few minutes?

Why they ask

They want to see calm, ordered thinking under pressure, and whether you communicate while you work.

How to answer

  • Confirm the scope from monitoring: is it the WAN link, the power, or the core switch.
  • Post a short status in the incident channel so people stop pinging you separately.
  • Check the carrier circuit, try the out-of-band console, and call the ISP or someone on site if needed.
  • Keep a timeline as you go so the post-incident review is easy.
12.How have you worked with cloud networking?

Why they ask

More networks now run partly in AWS, Azure or Google Cloud, and hiring managers want to know you won't be lost there.

How to answer

  • Name the concepts you've handled: VPCs or VNets, route tables, security groups, transit gateways.
  • Explain how you connected on-prem to the cloud, whether through VPN or a direct connection.
  • Mention a gotcha you learned, like overlapping IP ranges or asymmetric routing.
  • If your experience is light, say what you've done in a lab and what you'd want to learn.

Mistakes that sink good candidates

Listing certifications instead of answering the question

A CCNP gets you the interview, not the job.

Guessing confidently on a protocol detail you don't know

Say you'd check the docs or a lab, then reason out loud.

Blaming other teams in your stories

The network gets blamed constantly, and the good engineers don't pass it along.

Skipping the questions in a design exercise and jumping straight to drawing boxes

Need more Network Engineer interviews to prep for?

HeroApply applies to Network Engineer jobs that match you, every day. 1,908 jobs are open today.

Find Network Engineer jobs